Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I've been using Microsoft's one for my work accounts because, well, we're elbow deep into Office365 so why not.

I've never gotten that dialog, and have not had any issues with the accounts I've added. Since they're my work accounts, 99% of them share my work email as account name.

So does that mean I've just been lucky, in that the sites I've signed with have provided a sufficiently unique label? I feel I didn't fully get what the issue is.



I wanted to use a hardware key as 2FA but naturelly not all systems support it or not well enough (maximum of 1 key to register, are you f serious!!?), then had to choose something beacuse tick tock, this is not something that brings in bread to the family just a f nuisance to dig myself into what is out there and how good they are, just to be able to log in, what the hell, MS was mandated in a previous place, lets go for it, I wasted too much time already by trying to use my online accounts, not using it for meaningful work while playing with this sh around.

The whole online identification is seriously unreliable and full of big wholes, and much bigger risks, yet we build our whole life on top of it. Still using passwords after decades (Yes. Decades!) of serious harm caused by insecurities with it, and trying to patch with plasters or just some paint?! We are so damn stupid, almost no week goes by without some online system gives away serious bits or complete set of personal details of the masses easy to abuse and we just sit in the middle of the burning room like the coffee sipping doggy with that stupid hat and smile in the meme 'this is fine, this is fine'. Lets choose some longer than 8 character password, different for all system just to be safe, we are going to be fine, we are going to be fine.


Seems like the bug is specific to the iOS app when scanning QR codes.


Ah, using Android so I guess that's why. Weird though, given that Microsoft claims it's an intentional feature. Why wouldn't a feature like that be implemented in both platforms?

Even though it might be a dumb feature as seen from the users POV, it seems sufficiently special that it's something that I would assume one would want to have feature parity on.


I’ve been using MS Authenticator for a long time, mainly on iOS and I’ve never experienced this bug.


That's me (iOS scan the QR code) and I've never encountered the bug either.


Same. 3 personal accounts use the same email address. Two of them are FAANG and it all seems to fine (for going on a decade)


If you read Microsoft's response, they point at the companies issuing the MFA because -according to MSFT- "the companies are not entering the issuer in the label" and MSFT expect the issuer to be there.

I would imagine that, if that is their expectation, they would include the issuer in the label themselves, so, none of its products should have any issue.

The problem comes from using other provides -that use the "issuer" field to store the issuer (how quirky of them, amirite?)- while having the same email as identifier.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: